PT-2021-5542 · Apache+11 · Apache Http Server+11

Chamal

·

Published

2021-12-20

·

Updated

2026-03-10

·

CVE-2021-44790

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.51 and earlier
Description A carefully crafted request body can cause a buffer overflow in the mod lua multipart parser, specifically when the r:parsebody() function is called from Lua scripts. The Apache httpd team is not aware of an exploit for this issue, though it might be possible to craft one. This can potentially allow a remote attacker to execute arbitrary code by sending a specially formed HTTP request.
Recommendations For Apache HTTP Server versions 2.4.51 and earlier, consider disabling the mod lua module or restricting its use until a patch is available. As a temporary workaround, avoid using the r:parsebody() function in Lua scripts to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2022:0258
ALSA-2022_0258
ALSA-2025_16880
ALT-PU-2021-3574
ALT-PU-2021-3635
ALT-PU-2021-3637
ALT-PU-2022-1211
AZL-7044
BDU:2021-06392
BIT-APACHE-2021-44790
CESA-2022_0143
CESA-2022_0258
CVE-2021-44790
DLA-2907-1
DSA-5035-1
ELSA-2022-0143
ELSA-2022-0258
MGASA-2021-0577
OESA-2021-1473
OPENSUSE-SU-2022:0091-1
OPENSUSE-SU-2022_0091-1
OPENSUSE-SU-2024:11695-1
RHSA-2022:0143
RHSA-2022:0258
RHSA-2022:0288
RHSA-2022:0303
RHSA-2022:1136
RHSA-2022:1137
RHSA-2022:1138
RHSA-2022:1139
RHSA-2022_0143
RHSA-2022_0258
RLSA-2022:0258
RLSA-2022_0258
ROSA-SA-2023-2158
SUSE-SU-2022:0065-1
SUSE-SU-2022:0091-1
SUSE-SU-2022:0091-2
SUSE-SU-2022:0119-1
SUSE-SU-2022:0440-1
SUSE-SU-2022_0065-1
SUSE-SU-2022_0091-1
SUSE-SU-2022_0091-2
SUSE-SU-2022_0119-1
SUSE-SU-2022_0440-1
USN-5212-1
USN-5212-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu